Vishing & pretexting
SkillSecurityRun authorized voice-phishing (vishing) and pretext-based scenarios that test whether staff and help desks follow verification procedures, safely and by consent. Load after social-eng-methodology when the objective is phone/live-interaction based (help-desk password reset, MFA-reset abuse, pretext callback). Signals: "vishing", "call the help desk", "pretext", "test our verification process", "MFA reset social engineering".
Use Vishing & pretexting in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Vishing & pretexting and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Vishing & pretexting skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/social-eng/social-eng-vishing-pretext/SKILL.md and read by Ahel’s review.
When it applies
The engagement authorizes live-interaction testing (cleared via social-eng-methodology) and the
objective is a process test: will the help desk reset a password or MFA without proper verification?
Will an employee act on a convincing caller? This targets procedure adherence, which phishing
email can't measure. Help-desk MFA-reset abuse is a leading real-world initial-access vector, so
testing it is high-value.
Why it works
Voice adds urgency, authority, and social pressure that written channels lack — a confident caller
with a few true details (from recon-osint) and a plausible reason routinely gets a human to skip a
verification step. The finding is the gap in the verification procedure, not the individual who
answered.
Method
- Define the process under test and the pass/fail line with the client: e.g. "help desk must require callback-to-known-number + a second factor before any reset." The test measures whether that line holds.
- Build a proportionate pretext within allowed themes — a plausible role (a named-role, not a real named person, unless consented), a believable reason, and only the OSINT detail needed for credibility.
- Prepare a call plan and an immediate stand-down. Script the ask, the escalation, and the point at which you disclose. Keep the authorization/emergency contact ready if challenged.
- Execute a bounded number of attempts per RoE, tracking each: target, request, which verification steps were performed vs. skipped, and the outcome.
- Stop at the objective. Once a step is bypassed (or correctly refused), you have the result — do not proceed to actually reset/log in or take any real account action beyond proving the procedure gap; disclose per plan.
- Debrief. Capture where the procedure failed and why; hand it to the awareness/report step.
Gotchas
- Prove the gap, don't exploit it. A help desk agreeing to reset MFA is the finding — you do not complete a real takeover; stop and record it.
- De-escalate distress. If a target becomes anxious or suspicious, disclose the assessment and reassure them; their cooperation isn't the point, the procedure is.
- No coercion or protected topics — the excluded-theme and no-harm rules from
social-eng-methodologyapply in full over the phone. - Attribute cleanly — use test lines/tokens so a call can be confirmed as the assessment, and coordinate so it isn't mistaken for a real fraud attempt.
- Recording laws vary — only record calls where lawful and agreed in the RoE.
Verify success
A documented result per attempt — which verification steps held or failed and the outcome — with no real account actions taken and every target debriefed, feeding a procedure-focused report and remediation (stronger help-desk verification, callback policy, MFA-reset controls).
References
MITRE ATT&CK T1598.004 (phishing for information via voice), T1656 (impersonation); help-desk verification / MFA-reset hardening guidance.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
social-eng-vishing-pretext- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent